Showing 25 of 25 projects
A comprehensive collection of payloads and bypass techniques for web application security testing and penetration testing.
A comprehensive collection of payloads and bypass techniques for web application security testing and penetration testing.
A PowerShell post-exploitation framework for penetration testers, providing modules for code execution, persistence, reconnaissance, and credential theft.
Uses graph theory to map hidden attack paths in Active Directory environments for security analysis.
A PowerShell framework for offensive security, penetration testing, and red teaming with scripts for all phases.
A comprehensive, free information security reference covering techniques, tools, tactics, and resources for learning and professional development.
A simple Go-based tool to step down from root and execute a process as another user, designed for Docker containers.
A curated collection of cheat sheets and resources for penetration testing and security assessments.
A PowerShell toolkit for attacking, auditing, and securing Microsoft SQL Server environments during penetration tests.
A stealthy command and control framework that persists on webservers via a polymorphic PHP one-liner backdoor.
A Linux Kernel Module (LKM) rootkit for hiding processes, granting root privileges, and making files invisible.
A deprecated collection of PowerShell tools for offensive security operations and penetration testing.
An interactive command-line tool for exploring and exploiting the CTF protocol on Windows systems.
A tool for quickly evaluating IAM permissions and identifying security risks in AWS accounts through graph-based analysis.
A collection of Python scripts for AWS penetration testing, reconnaissance, exploitation, and persistence.
A tool for auditing and visualizing control paths in Active Directory to identify privilege escalation and resource access risks.
A collection of PowerShell scripts for security testing, penetration testing, and general system administration tasks.
A honeytoken-based tripwire for detecting Active Directory credential theft and privilege escalation attempts.
A modular attack toolkit for Azure DevOps Services that leverages the REST API for reconnaissance, privilege escalation, and persistence.
Visualizes AWS IAM and Organizations as a graph using Neo4j to identify security anomalies and privilege escalation paths.
A Linux/Unix privilege delegation tool using Role-Based Access Control (RBAC) to grant precise capabilities instead of full root access.
A proxy for docker.sock that enforces access control and isolated privileges for untrusted containers.
A curated collection of tips, commands, and strategies for solving Capture the Flag (CTF) challenges and HackTheBox machines.
A curated collection of tips, commands, and strategies for solving Capture the Flag (CTF) challenges and HackTheBox machines.
A Python script that implements security testing attacks against AWS Cognito, including account oracle and privilege escalation.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.